CVE-2026-6022
Analyzed
Analyzed - Analysis Complete
Uncontrolled Resource Consumption in Telerik RadAsyncUpload Causes Disk Exhaustion
Publication date: 2026-04-22
Last updated on: 2026-05-05
Assigner: Progress Software Corporation
Description
Description
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| progress | telerik_ui_for_asp.net_ajax | to 2026.1.421 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |